I am trying to implement HTTP Basic authentication with Spring Security for REST services based on JAX-RS Jersey and running on App Engine. I have found several examples and tutorials but it does not work for me. Whenever I access a resource no authentication is needed and 200 OK is retuned along with corresponding body.

Problem is solved. It seems that after first successful authorization FF or RESTClient keeps authorization header event though it is not displayed in the list of request headers so every time a request is sent it actually contains corresponding credentials. This is lesson for me not to use rich UI tools like RESTClient but rather tools like curl.
–
NathanNov 20 '12 at 7:23